Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

pomoc za uklanjanje virusa "windows\system32\winload.exe

[es] :: Zaštita :: pomoc za uklanjanje virusa "windows\system32\winload.exe

[ Pregleda: 4110 | Odgovora: 19 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon pomoc za uklanjanje virusa "windows\system32\winload.exe10.08.2010. u 19:26 - pre 166 meseci
Prilikom startovanja operativnog sistema javlja mi se sledeca poruka "path:\windows\system32\winload.exe". A kasnije pri startovanju bilo kog programa javlja mi se pitanje da li dozvoljavam da taj program izvrsi izmene...

Da li neko zna o cemu je rec, i molim za pomoc...

Unapred hvala.

Aleksandar
batica1981
 
Odgovor na temu

goran9888

Član broj: 171536
Poruke: 235
*.dynamic.isp.telekom.rs.



+18 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe10.08.2010. u 22:52 - pre 166 meseci
-Okaci slike tih obavestenja da vidimo o cemu je rec (i jednu i drugu)?
-Snimi sledeci file na Desktop, pokreni ga (desni klik pa Run As Administrator), sacekaj par sekundi da izadje log u Notepad-u i taj log mi prekopiraj u sledecoj poruci.


[Ovu poruku je menjao goran9888 dana 11.08.2010. u 00:10 GMT+1]
Prikačeni fajlovi
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe11.08.2010. u 00:00 - pre 166 meseci
@goran9888,
Citao sam dosta o ovome, koliko sam razumeo u pitanju je krah odnosno lose instaliran sistem...mora da se odradi format sistemske particije, zar ne? Ispravi me ako gresim...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe11.08.2010. u 01:47 - pre 166 meseci
Gorane,

Saljem ti log, a sliku trenutno ne mogu da snimim, jer se sada nista ne desava...

Hvala


Volume in drive C is OS
Volume Serial Number is 92E2-FBBC

Directory of C:\Windows\System32

13/07/2009 07:43 PM 604,192 winload.exe
1 File(s) 604,192 bytes

Directory of C:\Windows\System32\Boot

13/07/2009 07:43 PM 604,192 winload.exe
1 File(s) 604,192 bytes

Directory of C:\Windows\winsxs\amd64_microsoft-windows-b..environment-windows_31bf3856ad364e35_6.1.7600.16385_none_c52d88d1a67ba4c0

13/07/2009 07:43 PM 604,192 winload.exe
1 File(s) 604,192 bytes

Directory of C:\Windows\winsxs\amd64_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7600.16385_none_b71babd98657e6ef

13/07/2009 07:43 PM 604,192 winload.exe
1 File(s) 604,192 bytes

Total Files Listed:
4 File(s) 2,416,768 bytes
0 Dir(s) 245,958,651,904 bytes free

batica1981
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe11.08.2010. u 03:53 - pre 166 meseci


Evo upravo se javio virus.

Imam problem jer ne mogu da ti posaljem slike. Ne dozvoljava mi da uradim bilo sta osim da kliknem na yes ili no (verovatno postoji neki nacin, ali ja ga ne znam).

Ono sto mogu da uradim je da napisem sta se konkretno javlja.
Kada, recimo, hocu da startujem Windows Media Player desava se sledece:

User Account Control
Do you want to allow the following program to make changes to this computer?
Program name: Windows Media Player
Verified publisher: Microsoft Windows
Program location: "c:\Program Files (x86)\Windows Player\wmplayer.exe"/prefetch:1

Nakon toga bilo sta na tastaturi da pritisnem, otvara se novi prozor ili selektuje celu stranicu...

Nadam se da ovo pomaze.


batica1981
 
Odgovor na temu

goran9888

Član broj: 171536
Poruke: 235
217.16.130.*



+18 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe11.08.2010. u 09:23 - pre 166 meseci
Citat:
Evo upravo se javio virus.


To nije virus, vec ti se javio UAC (User Account Control) koji ti je ukljucen.
Da li koristis antivirus? Koji antivirus je u pitanju?


Ukoliko sumnjas da postoji malware na tvom racunaru isprati sledece uputstvo:

- Download-uj Malwarebytes' Anti Malware sa sledeceg link-a: http://fileforum.betanews.com/...ytes-AntiMalware/1186760019/1;
- Nakon instalacije programa, update-uj ga i pokreni Full scan;
- U sledecoj poruci okaci log koji MBAM bude izbacio nakon zavrsenog scan-a.


Sto se tice te greske na samom startu OS-a:
- okaci mi screnshoot greske
- start -> run -> msconfig -> kartica StartUp . Okaci SS prozora.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 04:22 - pre 166 meseci
Saljem ti log, a screan shot nisam uspeo. Danas ceo dan nisam mogao da koristim tastaturu, jednostavno mi blokira koriscenje.

Koristim McAfee kao zastitu.

Log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4420

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

11/08/2010 3:27:18 PM
mbam-log-2010-08-11 (15-27-18).txt

Scan type: Full scan (C:\|)
Objects scanned: 257644
Time elapsed: 52 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 8
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> No action taken.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files (x86)\Perfect Optimizer (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup\Application (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Backup\Service (Rogue.PerfectOptimzier) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\Temp (Rogue.PerfectOptimzier) -> No action taken.

Files Infected:
C:\$Recycle.Bin\S-1-5-21-2229183119-1739370019-4094606514-1000\$RT4BLJE.exe (PUP.PerfectOptimizer) -> No action taken.
C:\Program Files (x86)\Perfect Optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> No action taken.
batica1981
 
Odgovor na temu

goran9888

Član broj: 171536
Poruke: 235
217.16.130.*



+18 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 07:27 - pre 166 meseci
-Pokreni opet Malwarebytes' Anti Malware;
-Uradi full scan
-Nakon zavrsenog scan-a klikni Ok, pa onda Show Results, proveri da je sve stiklirano pa klikni na Remove Selected
-U sledecoj poruci mi okaci log koji ti MBAM bude izbacio.




Citat:
Koristim McAfee kao zastitu.


Kupio si licencu za njihov AntiVirus Plus ili ...?
Ukoliko nisi, preporucujem ti da instaliras neko free resenje tipa: Avira, Avast, AVG, Panda Cloud Free, itd.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 19:03 - pre 166 meseci

McAfee SECURE, sam dobio kada sam kupio laptop, sa licencom od 18 meseci...



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4420

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

12/08/2010 11:47:34 AM
mbam-log-2010-08-12 (11-47-34).txt

Scan type: Full scan (C:\|)
Objects scanned: 257181
Time elapsed: 54 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 8
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\.pox (Rogue.FixTool) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\pofile (Rogue.FixTool) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files (x86)\Perfect Optimizer (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Application (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FirstBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Registry\FullBackup (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Backup\Service (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.
C:\Program Files (x86)\Perfect Optimizer\Temp (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files (x86)\Perfect Optimizer\PerfectOptimizer.ini (Rogue.PerfectOptimzier) -> Quarantined and deleted successfully.

batica1981
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 19:44 - pre 166 meseci
Da li je sad bolje stanje?
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 19:50 - pre 166 meseci

Da bolje je, za sada se nista ne desava.

Ali i dalje pri startovanju operativnog sistema javlja se poruka "path:\windows\system32\winload.exe"
batica1981
Prikačeni fajlovi
 
Odgovor na temu

goran9888

Član broj: 171536
Poruke: 235
*.dynamic.isp.telekom.rs.



+18 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 21:22 - pre 166 meseci
Sto se tice te greske na samom startu OS-a:
- okaci mi screnshoot greske
- start -> run -> msconfig -> kartica StartUp . Okaci SS prozora.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe12.08.2010. u 22:52 - pre 166 meseci


Upload-ovao sam ti na moj prethodni odgovor, nadam se da si to trazio...
batica1981
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 02:19 - pre 166 meseci
Da bi mogli da vidimo screenshot, potrebno je da uradis sledece:
Start>Run>msconfig>StartUp...
Kada otvoris prozor, idi na Start, zatim Search i pronadji Snipping Tool, to je alat koji je sastavni deo Windows 7-ce...pokreni ga i pomocu njega jednostavno obuhvati i iseci ceo prozor StartUp kartice koje si prethodno pokrenuo...sacuvaj screenshot i odradi Upload uz poruku uz tvoj poslednji post...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 18:36 - pre 166 meseci
Nisam mogao da uradim snap iz jednog dela vec iz dva dela.

Nadam se da je ovo sto cu da upload-ujem ono sto si trazio.

batica1981
Prikačeni fajlovi
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 19:13 - pre 166 meseci
To je to, medjutim ne mogu iz prilozenog da vidim sve detaljno, jer je skupljeno i nepregledno...
Skini HijackThis odavde http://download.cnet.com/Trend...8022_4-10227353.html?tag=mncol , prebaci ikonicu na desktop (obavezno), preimenuj je recimo u "12345.exe", pokreni...odaberi "Do a system scan and save a logfile"...kada zavrsi, kopiraj log file ovde...

A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 19:50 - pre 166 meseci


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:10 PM, on 13/08/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Users\Ica-Bata\Desktop\uTorrent.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Ica-Bata\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/23
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100731112016.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Ica-Bata\Desktop\uTorrent.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Dell Remote Access.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13780 bytes

batica1981
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 20:09 - pre 166 meseci
Da sam ja na tvom mestu ne bih se zamajavao sa ovim problemom, jednostavno bi formatirao hard i odradio novu instalaciju sistema...ne znam uopste kako da definisem ovo sto je SystemRoot podivljao...neka kolege daju svoje misljenje, mada mi deluje totalno zamrseno...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

aleksandar.bata
batica1981
regina, canada

Član broj: 264688
Poruke: 10
*.regn.hsdb.sasknet.sk.ca.



Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe13.08.2010. u 20:13 - pre 166 meseci

Ok, hvala u svakom slucaju.
batica1981
 
Odgovor na temu

goran9888

Član broj: 171536
Poruke: 235
*.dynamic.isp.telekom.rs.



+18 Profil

icon Re: pomoc za uklanjanje virusa "windowssystem32winload.exe14.08.2010. u 09:12 - pre 166 meseci
@aleksandar.bata

Procitaj PP.
HJT log "nije dobar".
 
Odgovor na temu

[es] :: Zaštita :: pomoc za uklanjanje virusa "windows\system32\winload.exe

[ Pregleda: 4110 | Odgovora: 19 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.